docs: hub v0.61.0 Customer RESET — REPORT/CONTEXT + ep0 runbook §10 (tenantsync v1.1.0 deprovision, live-drilled)

This commit is contained in:
2026-07-17 13:15:57 +02:00
parent e144c5e491
commit 7c9647327f
3 changed files with 74 additions and 48 deletions
+16
View File
@@ -3,6 +3,22 @@
> Created with the REUSE.md rollout (2026-07-03). Authoritative history: `hub/CHANGELOG.md` (hub),
> `website/CHANGELOG.md`, `scripts/CHANGELOG.md`; end-of-task detail in `REPORT.md`.
- **2026-07-17 — CUSTOMER RESET SHIPPED: hub v0.61.0 + felhom-tenantsync v1.1.0 (LIVE).** The middle
lifecycle tier (host delete < RESET < customer Delete). One operator action → pre-first-install: all
OPERATIONAL state dies (offsite repo, PBS namespace+backups, DR recipe, one-time secret, claim state,
retained escrow custody); IDENTITY + basic config (incl. the offsite tier CHOICE) + provenance + events
SURVIVE. Rulings: separate escrow-custody ack; clears claim (fresh code next onboarding); REFUSES while
any host row exists; live-counted confirm inventory. Discipline: external teardown FIRST, DB purge LAST,
every leg idempotent → partial run re-runs from the top (purge withheld until externals ok). New:
`store/customer_reset.go` (journal+inventory+ack-gated purge), `claim.ResetToUnclaimed`,
`offsite.{Deprovision,OffsiteIdentifier,ClearProvisionedDescriptor}`, `tenantsync.Deprovision` +
`felhom-tenantsync.sh` **deprovision** op (v1.1.0, destroys ns+groups+token, shared user untouched),
`web/customer_reset.go` (GET inventory JSON / POST orchestration) + an **amber** RESET card distinct
from the red Danger-zone Delete. Red-proofs: ack-gate + partial-failure resumability (both proven red).
**Live-drilled on ep0** (throwaway `drill-reset-01` with a real backup): deprovision `deleted:true`,
idempotent re-run `deleted:false`, all 3 real tenants survived. Hetzner-delete + the password-gated web
POST covered by tests (offsite Deprovision mirrors live-proven ReissueCredentials). See REPORT.md.
- **2026-07-17 — HOST-DELETE DEMOTES ESCROW: hub v0.60.1 (LIVE).** Closes the v0.60.0 review gap:
`DeleteHost(deleteEscrow=true)` now DEMOTES the current escrow blob into `host_escrow_superseded`
(copy-before-delete, same tx) + spares existing superseded rows — never destroys custody. The